CVE-2026-77703: SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine
Published Sep 24, 2026
·Updated
Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM).
This issue affects Liman Render Engine: from 1.0 before 1.2-75.
Affected Software
1 affected component
HAVELSAN Liman Render Engine>=1.0<1.2-75
Event History
Sep 24, 2026
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
HAVELSAN Liman Render Engine versions from 1.0 up to, but not including, 1.2-75 are affected.
2
What does an attacker need to exploit this issue?
An attacker must be able to act as an adversary in the middle during SSH key exchange. The CVSS vector indicates exploitation is network-based, requires high attack complexity, and does not require privileges or user interaction.
3
What is the security impact if exploitation succeeds?
Successful exploitation can expose confidential information. The provided scoring indicates no integrity or availability impact.